From: gufus on
Hello, David!

You wrote on Sat, 3 Apr 2010 17:24:49 -0400:

DHL> No, quarantine not delete.

Yes.

I stand corrected. :-)

--
With best regards, gufus. E-mail: stop.nospam.gbbsg(a)shaw.ca


From: FromTheRafters on
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:hp8bn301r6h(a)news3.newsguy.com...
> From: "gufus" <stop.nospam.gbbsg(a)shaw.ca>
>
> | Hello, FromTheRafters!
>
> | You wrote on Sat, 3 Apr 2010 14:14:21 -0400:
>
> | |
> || You could submit the suspect file to virustotal.com, jotti.org, or
> || virscan.org to see what other antimalware engines have to say.
>
>
> | Yep, could be positive-negative.. delete it to be /sure/ though.
>
> No, quarantine not delete.

I was going to point that out, but as this seems to be a temp file I
figured why not - it would lilkely be created anew next time.


From: Buffalo on


David H. Lipman wrote:
> From: "gufus" <stop.nospam.gbbsg(a)shaw.ca>
>
>> Hello, FromTheRafters!
>
>> You wrote on Sat, 3 Apr 2010 14:14:21 -0400:
>
>> |
>>> You could submit the suspect file to virustotal.com, jotti.org, or
>>> virscan.org to see what other antimalware engines have to say.
>
>
>> Yep, could be positive-negative.. delete it to be /sure/ though.
>
> No, quarantine not delete.
BTW. what does quarantining actually do? Just change the extension or ?
Buffalo


From: David H. Lipman on
From: "FromTheRafters" <erratic(a)nomail.afraid.org>

| "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
| news:hp8bn301r6h(a)news3.newsguy.com...
>> From: "gufus" <stop.nospam.gbbsg(a)shaw.ca>

>> | Hello, FromTheRafters!

>> | You wrote on Sat, 3 Apr 2010 14:14:21 -0400:

>> | |
>> || You could submit the suspect file to virustotal.com, jotti.org, or
>> || virscan.org to see what other antimalware engines have to say.


>> | Yep, could be positive-negative.. delete it to be /sure/ though.

>> No, quarantine not delete.

| I was going to point that out, but as this seems to be a temp file I
| figured why not - it would lilkely be created anew next time.


That is a *very* good point.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


From: David H. Lipman on
From: "Buffalo" <Eric(a)nada.com.invalid>



| David H. Lipman wrote:
>> From: "gufus" <stop.nospam.gbbsg(a)shaw.ca>

>>> Hello, FromTheRafters!

>>> You wrote on Sat, 3 Apr 2010 14:14:21 -0400:

>>> |
>>>> You could submit the suspect file to virustotal.com, jotti.org, or
>>>> virscan.org to see what other antimalware engines have to say.


>>> Yep, could be positive-negative.. delete it to be /sure/ though.

>> No, quarantine not delete.
| BTW. what does quarantining actually do? Just change the extension or ?
| Buffalo


It depends on the software but it ususlly envloves placing the suspect file in an
encrypted "container" such that it is not accessible by any other software or process
other than the anti virus application iself.

It is akin to locking a patient with Bubanic Plague in a hospital isolation room/ward.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp